Settings
ArcadeDB allows changing settings at JVM (server or embedded) and per database level.
| Server/Embedded (JVM) Level | Database Level |
|---|---|
Those settings are valid for all the databases open in the same Server or JVM when run embedded. If defined, they override the default value (look at the table below to see the default values). They are used only if a database does not override them. Such settings are not saved, so you need to set them everytime. |
Database level settings are stored in the database and override the Server/Embedded (JVM) settings if present. You can change these settings via SQL or API when run embedded. |
JVM startup (server/embedded only)
All the settings modified at JVM startup are not persistent and need to be set everytime you’re running ArcadeDB server or your embedded application.
If you’re updating a setting at JVM level, prefix the setting name with arcadedb. by using this syntax:
$ java ... -Darcadedb.<name>=<value> ...
Where <name> is the name of the setting and <value> the value you want to override.
Example to change the server mode from development (default) to production:
$ java ... -Darcadedb.server.mode=production ...
Example to increase the default page size for buckets to 1 MB:
$ java ... -Darcadedb.bucketDefaultPageSize=1048576 ...
Alternatively, these settings can be set via the environment variable ARCADEDB_SETTINGS, which the
launcher scripts (bin/server.sh, bin/console.sh and friends) put on the JVM command line:
ARCADEDB_SETTINGS="-Darcadedb.server.rootPassword=playwithdata" bin/server.sh
JAVA_OPTS is passed through as well, but it is meant for JVM flags: keeping settings in
ARCADEDB_SETTINGS means overriding one variable never discards the other.
Boolean values
A setting of type Boolean accepts only true or false (in any casing, surrounding spaces are ignored). Anything
else — yes, 1, on, or a misspelling such as ture — is refused: the setting keeps its default and a warning
naming the setting and the rejected value is logged at startup. This holds however the value is provided: a JVM system
property, an environment variable, ARCADEDB_SETTINGS, the server configuration file, or an admin command.
(The server configuration file is checked this way since v26.10.1.)
The point is that a typo can never quietly mean false. For a setting that guards something — for example
ha.tls.mutualAuth or ha.peerAllowlist.enabled, both of which default to true — silently reading an unrecognised
value as false would have turned the protection off while it looked enabled. If a setting is not taking effect,
check the server log for that warning.
Settings with a fixed list of values
Some settings accept only a given set of words — server.mode is development, test or production, for
instance. Since v26.10.1 a value outside the list is refused wherever it is written, including the server
configuration file, and the setting keeps its previous value with a warning naming what was allowed. Casing does not
matter: Production is accepted and understood the same as production.
Setting names
A setting name is case-insensitive, and the arcadedb. prefix is optional in the server configuration file: server.mode,
Server.Mode and arcadedb.server.mode all name the same setting. (Since v26.10.1. Before that, a name written in a
different case was accepted and then ignored, so the setting silently kept its default — with nothing in the log to say
so, and, for settings that log what they do at startup, with every appearance of having been applied.)
A name in the server configuration file that matches no setting — a typo, or a leftover from an older version — is ignored and reported with a warning naming it, so it no longer disappears in silence.
Server-level settings
A setting documented as server level can be written in the server configuration file, with SET SERVER SETTING, or as
a -D JVM property, and all three take effect. (Before v26.10.1 a number of them were only ever read from -D or an
environment variable: a value written in the configuration file was accepted and then ignored, with nothing in the log
to say so. This affected, among others, server.mode and studio.enabled, the HA snapshot and peer-allowlist
settings, and the ports and limits of the Bolt, Postgres, Redis and gRPC protocols.)
A setting that accepts only a fixed set of values — server.mode, ha.quorum, ha.serverRole and the others whose
description lists their values — refuses anything outside that set, whichever channel writes it: the configuration
file, a -D property, SET SERVER SETTING, ALTER DATABASE … SETTING, the gRPC settings call or the
set_server_setting MCP tool. The setting keeps the value it had and the refusal names the values it accepts.
|
(Since v26.10.1.) Before this, the administrative channels stored an unaccepted value without complaint. A typo such
as If you have scripts that write one of these settings, check the values they send before upgrading: a value that was silently ignored before now returns an error. |
SQL (Database Level)
All the changes executed via SQL Alter Database command are relative to the current database only and are persistent. Here is an example to increase the default page size for buckets to 1 MB:
ALTER DATABASE `arcadedb.bucketDefaultPageSize` 1048576
The current settings can be listed from SQL using:
SELECT expand(settings) FROM schema:database
Programmatically (Server/Embedded and Database levels)
You can access to the database configuration with database.getConfiguration() to read and write per database settings.
Example to increase the default page size for all the buckets to 1 MB on the current database:
database.getConfiguration().setValue(GlobalConfiguration.BUCKET_DEFAULT_PAGE_SIZE, 1048576);
To change a setting at Server/Embedded (JVM) level, set the value in the GlobalConfiguration enum.
Example to increase the default page size for buckets to 1 MB for all the databases open in the current JVM (server/embedded):
GlobalConfiguration.BUCKET_DEFAULT_PAGE_SIZE.setValue(1048576);
Available settings by scope (in alphabetic order):
The tables that follow contains all the available settings in ArcadeDB separated by scope:
-
JVM, as the settings applied at the JVM level, so to both clients and servers -
SERVER, as the settings that only apply to the ArcadeDB Server. If you’re embedding a server in your Java application you can use these settings -
DATABASEare all the settings that can be saved in the database configuration and are restored once the database is open
JVM
| Name | Description | Type | Default Value |
|---|---|---|---|
|
Dumps the configuration at startup |
Boolean |
false |
|
Dumps the metrics at startup, shutdown and every configurable amount of time (in seconds) |
Long |
0 |
|
Number of bits reserved for the bucketId when packing a RID into the numeric value returned by the Cypher |
Integer |
16 |
|
Specify the preferred profile among: default, high-performance, low-ram, low-cpu |
String |
default |
|
Percentage of |
Integer |
80 |
|
Maximum number of requests of remote clients that may run at once in the JVM, across every database (see Concurrent Requests for how the queue works and how to size it). It counts every HTTP request that runs work in a database (query, command, batch load, vector and full-text search, time series, PromQL and Grafana), and the requests received over Postgres, BOLT, Redis, gRPC, Gremlin Server, MCP and MongoDB. A request that arrives when this many are running, or when the heap the running queries hold reserved is above |
Integer |
(2 x cores, min 4) |
|
Maximum heap (in MB) the in-memory buffers of all the queries running in the JVM may hold at once, across every database: the rows an |
Long |
(heap/2) |
|
Maximum number of queries that may wait in the queue of the query admission gate (see |
Integer |
256 |
|
Maximum time in milliseconds a query waits in the queue of the query admission gate (see |
Long |
30000 |
|
Size, in RID positions, of the window the |
Integer |
16384 |
|
Tells if it is running in test mode. This enables the calling of callbacks for testing purpose |
Boolean |
false |
Available Plugins
The following plugins are available for ArcadeDB Server:
-
MongoDB(com.arcadedb.mongo.MongoDBProtocolPlugin) - Implements the MongoDB wire protocol -
Postgres(com.arcadedb.postgres.PostgresProtocolPlugin) - Implements the Postgres wire protocol -
Redis(com.arcadedb.redis.RedisProtocolPlugin) - Implements the Redis wire protocol -
Http(com.arcadedb.server.http.HttpServerPlugin) - Implements the HTTP/REST API -
gRPC(com.arcadedb.server.grpc.GrpcServerPlugin) - Implements the gRPC API. Bundled in thefulldistribution but not started until it is added toserver.plugins(see gRPC settings)
SERVER
| Name | Description | Type | Default Value |
|---|---|---|---|
|
State of backup lock. Disable for increased performance of massive insertions. |
Boolean |
True |
|
Milliseconds to wait for a TCP connection to a peer’s Raft address before an add-peer request ( |
Long |
2000 |
|
AppendEntries batch byte limit for replication (e.g. '32MB'). |
String |
32MB |
|
Maximum number of Raft log entries per AppendEntries batch. Bounds the per-batch in-memory footprint on the follower during catch-up resync, where many batches may queue before the state machine can apply them. Lowering this value reduces peak heap pressure on followers catching up from a far-behind state. The byte limit ( |
Integer |
64 |
|
Number of retries performed by RemoteDatabase after receiving HTTP 503 NeedRetryException during an election. |
Integer |
3 |
|
Delay in ms between RemoteDatabase election retries. A longer |
Long |
2000 |
|
When true (default), at first cluster formation peers exchange |
Boolean |
true |
|
Maximum time in ms the bootstrap leader waits for every configured peer to report its bootstrap state before proceeding. |
Long |
120000 |
|
Cluster name. Useful in case of multiple clusters in the same network |
String |
arcadedb |
|
Shared secret for inter-node authentication. If empty, auto-generated at first startup and persisted under |
String |
|
|
Path to a file containing the shared secret for inter-node authentication. Read only when |
String |
null |
|
How long in ms a follower must stay stuck at a stale term, without its applied index advancing, before it reformats its Raft storage and rejoins. Any advance of the applied index restarts the window. Floored at 2x |
Long |
20000 |
|
Minimum Raft election timeout in ms. Increase for high-latency WAN clusters. |
Integer |
5000 |
|
Maximum Raft election timeout in ms. Increase for high-latency WAN clusters. Must be above |
Integer |
10000 |
|
True if HA is enabled for the current server |
Boolean |
false |
|
Number of automatic retries in case of IO errors with a specific server. 0 (default) is to retry against all the configured servers |
Integer |
0 |
|
Rate-limiting interval in ms for DNS re-resolution in the gRPC peer address allowlist filter. |
Long |
30000 |
|
gRPC flow control window size in bytes for Raft AppendEntries traffic. Larger values help catch-up replication after partitions. |
Long |
4194304 |
|
Maximum number of Raft log entries to batch in a single group commit flush. Higher values improve throughput under concurrent load. |
Integer |
500 |
|
Timeout in ms waiting for space in the group-commit queue before throwing ReplicationQueueFullException. |
Integer |
100 |
|
Maximum pending transactions allowed in the Raft group-commit queue. When full, the server sheds load by throwing ReplicationQueueFullException (NeedRetryException). |
Integer |
10000 |
|
How long in ms the RPCs still running on a Raft gRPC connection that reached |
Long |
5000 |
|
How long in ms an inbound Raft gRPC connection may live before the server closes it with a graceful GOAWAY, whether busy or idle. Bounds a connection that is never idle, such as a removed peer that keeps campaigning, at the price of recycling healthy replication streams once per period. gRPC applies a +/-10% jitter and a 1 second floor. Set it well above the Raft election timeout. |
Long |
0 |
|
How long in ms an inbound Raft gRPC connection may carry no RPC before the server closes it with a graceful GOAWAY. Closes quiet connections, such as the socket of a peer removed from the allowlist; it never reaps an active replication stream. Values below 1 second are raised to 1 second. |
Long |
300000 |
|
Interval in ms for the Raft health monitor to check for CLOSED/EXCEPTION state and auto-recover. Since v26.9.1 the same tick also restarts in place a node whose Raft log writer failed (for example |
Long |
3000 |
|
Maximum size in bytes of a single response body eligible for caching in the HTTP idempotency cache. Larger responses are not cached, so a retry of that request executes again. See reference/http-api/http.adoc#http-request-replay |
Long |
1048576 |
|
Maximum total size in bytes of the cached response bodies in the HTTP idempotency cache. Oldest entries are evicted when exceeded. |
Long |
67108864 |
|
Maximum number of entries in the HTTP idempotency cache. |
Integer |
10000 |
|
Time-to-live in ms for entries in the HTTP idempotency cache: how long a retry with the same |
Long |
60000 |
|
JVM-pause length in ms above which Ratis closes this node’s Raft division (Ratis default: 60000). |
Long |
0 |
|
The server is running inside Kubernetes (enables auto-join on scale-up) |
Boolean |
false |
|
When running inside Kubernetes use this suffix to reach the other servers. Example: arcadedb.default.svc.cluster.local |
String |
|
|
Number of Raft log entries retained after a snapshot as a buffer for slightly lagging followers. Lower values free disk faster but raise the chance a slow follower needs a full snapshot resync. |
Integer |
1024 |
|
When true, deletes old Raft log segments after each snapshot to bound disk growth. Set to false to retain full log history for debugging/auditing. |
Boolean |
true |
|
Maximum Raft log segment size (e.g. '64MB', '128MB'). |
String |
64MB |
|
Verbose HA logging: 0=off, 1=basic (elections), 2=detailed (replication), 3=trace (every state machine apply). |
Integer |
0 |
|
Time in ms an add-peer or remove-peer keeps re-issuing the Raft configuration change before reporting it as not committed. Bounds the whole request, not one attempt: an attempt that cannot finish in what is left of the budget is not started. A peer that answers a connection but never catches up (a legitimately large snapshot install, or a listener that is not a peer of this cluster) is what reaches the full budget; a peer that belongs to a different cluster is refused at once instead. Lower it below a load balancer’s idle timeout so you get the error rather than a dropped connection, remembering that an attempt whose network call hangs can take up to about 31s on its own. Read at server start. |
Long |
90000 |
|
Reject inbound Raft gRPC connections whose remote address does not resolve to a cluster peer. The accepted hosts are those in |
Boolean |
true |
|
Startup grace window in ms during which the gRPC peer allowlist fails OPEN (accepts and logs a warning) for an unmatched address, as long as it has never resolved every host in |
Long |
60000 |
|
How long in ms the gRPC peer allowlist keeps the last successfully-resolved IPs of a peer host when a later DNS re-resolution of that host fails. Bridges transient DNS outages and pod-IP churn so a peer that resolved moments ago is not evicted by a momentary lookup failure. 0 disables stickiness. |
Long |
300000 |
|
Time in ms a follower must stay continuously unreachable before the leader resets that one follower’s replication gRPC channel, so the next send re-resolves DNS and reconnects. Recovers a leader appender stuck on a stale DNS result after a follower restarts with a new address (e.g. a Kubernetes pod-IP change). Retried once per interval, up to 5 attempts, then the leader gives up or escalates (see |
Long |
60000 |
|
When the |
Boolean |
true |
|
Time in ms since the last successful RPC to a follower before the leader reports it as unreachable in the resync narrative. Also the "unreachable" signal |
Long |
10000 |
|
Timeout in ms a follower waits for the leader to answer a batch load it relayed via |
Long |
600000 |
|
Fallback timeout in ms a follower waits for the leader to answer a forwarded SQL/DDL write, used only when the database has no |
Long |
3600000 |
|
Connect timeout in ms for the leader proxy (replica-to-leader forwarding). Since 26.10.1 it also applies when the cluster uses SSL, where the connection previously had a fixed 5s timeout the setting could not change. Read when the connection is created, so a change needs a restart. |
Long |
5000 |
|
Milliseconds a follower waits for the leader to answer a forwarded |
Long |
3600000 |
|
Read timeout in ms for the leader proxy. Covers long-running queries forwarded from a replica. |
Long |
30000 |
|
Write quorum: |
String |
majority |
|
Timeout in ms waiting for the quorum acknowledgment |
Long |
10000 |
|
TCP/IP port for Raft gRPC communication. Used as the default when HA_SERVER_LIST entries do not specify an explicit port. |
Integer |
2434 |
|
If true, the Raft storage directory is preserved across restarts, enabling node rejoin by replaying its persisted log instead of a full snapshot resync. Defaults to |
Boolean |
true |
|
Parent directory under which the per-node Raft storage sub-folders ( |
String |
|
|
Maximum consecutive Ratis restart attempts by the health monitor before the server shuts down for cluster-level recovery. Also bounds, per incident, the in-place restarts that recover a failed Raft log writer (since v26.9.1). |
Integer |
10 |
|
Default read consistency for replica reads: |
String |
read_your_writes |
|
Maximum channel chunk size for replicating messages between servers |
Integer |
16777216 |
|
Raft log index gap threshold for replication lag warnings. 0 to disable. |
Long |
1000 |
|
Ships a schema change to the followers as a delta against the schema they already hold, instead of the whole schema document on every DDL. On a large schema that is kilobytes instead of megabytes per Raft entry. The leader sends the whole document anyway after it becomes leader, for a compaction entry, an entry shipped in instalments, a change too large for a delta to pay off, and whenever any peer has not confirmed it can decode a delta, so a rolling upgrade needs no ordering. A rolling downgrade to a version older than v26.10.1 does: see Schema delta replication. While on, the leader keeps one parsed copy of the schema per replicated database in heap. Turning it off is safe at any time. (Since v26.10.1) |
Boolean |
true |
|
A follower applying a DDL entry creates only the components for the files that entry added, instead of rebuilding every component in the database. The full rebuild costs time proportional to all the files per entry, which made building a large schema quadratic (a 1209-type schema took about 2h53m to replicate). Entries the incremental path cannot express (a file retired, a compacted index, a bloom filter, a new dictionary) fall back to the full rebuild on their own. Read per entry, so a change takes effect without a restart. Set to |
Boolean |
true |
|
Have every transaction a node replicates carry the Raft log index that node had applied when the transaction began, so the leader can refuse a transaction prepared before a schema change it has already applied. Without it a replica that has not yet applied a committed |
Boolean |
true |
|
How long in ms |
Long |
30000 |
|
Refuse a group or API-token change (HTTP 409 / gRPC |
Boolean |
true |
|
Time budget in ms a peer-admission call ( |
Long |
3000 |
|
Servers in the cluster, comma-separated. Each entry uses the readable object form |
String |
|
|
Node role in the cluster: |
String |
any |
|
DEFLATE level the leader applies to the ZIP stream of a database snapshot shipped to a follower: 0 (stored) to 9 (smallest, slowest), or -1 for the Deflater default (level 6). A value outside -1..9 is ignored and the default is used. Only the serving side reads it. Since v26.11.1: default changed from -1 to 1 |
Integer |
1 |
|
Read timeout in ms for downloading a database snapshot from the leader during follower resync. |
Integer |
300000 |
|
Maximum acceptable gap between the snapshot index and persisted applied index before triggering a snapshot download. |
Long |
10 |
|
Milliseconds a snapshot install, or the apply of a replicated drop database, waits for a backup, export or import of the same database already running on this node before it replaces or drops the database files anyway (logging a warning). |
Long |
60000 |
|
Maximum retry attempts for snapshot download from the leader during snapshot installation. |
Integer |
3 |
|
Base delay in ms for exponential backoff between snapshot download retries. Actual delay is baseMs * 2^attempt. |
Long |
5000 |
|
Maximum number of concurrent snapshot downloads served by the leader. Requests over this limit receive HTTP 503. |
Integer |
2 |
|
Maximum uncompressed size in bytes for a single entry in a snapshot ZIP. Decompression-bomb guard. Set 0 or a negative value to keep the built-in default: the guard cannot be switched off. Configurable since v26.10.1 |
Long |
10737418240 |
|
Number of Raft log entries after which the leader automatically takes a snapshot. |
Long |
100000 |
|
Delay in ms before the snapshot-gap watchdog triggers a download. Floored at 4x |
Long |
30000 |
|
Timeout in ms for writing a snapshot to a follower. If the transfer stalls beyond this duration, the connection is force-closed. |
Long |
300000 |
|
How long in ms a replica must stay continuously STALLED — its |
Long |
60000 |
|
After a phase-2 replication failure, step-down is attempted first. If every step-down fails and this flag is true, the JVM exits so an orchestrator can restart. Default is false: the server keeps running and logs CRITICAL. |
Boolean |
false |
|
Negotiate TLS on the Raft gRPC transport, which carries AppendEntries, RequestVote and the Ratis admin/client calls between the nodes of a cluster. When true, |
Boolean |
false |
|
PEM file holding this node’s Raft gRPC certificate followed by any intermediate CA certificates. The certificate must carry a subject alternative name matching the address the other nodes use to dial this node in |
String |
|
|
PEM file holding the PKCS#8 private key that matches |
String |
|
|
PEM file holding the cluster CA certificate(s) that sign every node certificate. A peer presenting a certificate this collection does not chain to is rejected during the TLS handshake, before any Raft message is read. Required when |
String |
|
|
Require the dialing peer to present a client certificate signed by the CA collection in |
Boolean |
true |
|
Raft log write buffer size (e.g. '40MB'). Must be at least |
String |
40MB |
|
Number of automatic retries in case of IO errors with a specific server. If replica servers are configured, look also at |
Integer |
0 |
|
Upper bound, in milliseconds, on how long the remote client honors the |
Long |
30000 |
|
TCP/IP Socket timeout (in ms) |
Integer |
30000 |
|
Connect timeout, in milliseconds, for an outbound fetch of a URL you supply - |
Integer |
30000 |
|
Read timeout, in milliseconds, for an outbound fetch of a URL you supply - |
Integer |
30000 |
|
Maximum number of connections a binary wire-protocol listener (Postgres, Redis, BOLT) may hold in the phase before authentication. Each accepted socket costs one thread and one file descriptor before the client has proved who it is, and |
Integer |
500 |
|
Enable TCP keepalive (SO_KEEPALIVE) on every wire-protocol socket. The Postgres and Redis executors drop the socket read timeout to infinite once a connection is authenticated, because an authenticated client legitimately holds an idle connection open, and those protocols carry no application-level heartbeat. With keepalive off, a peer that dies without a FIN/RST (host crash, silent partition) leaves the server thread blocked in a read forever, leaking a thread and a file descriptor per event. Keepalive lets the OS discover the dead peer and fail the read. Since v26.9.1 |
Boolean |
true |
|
Seconds an authenticated connection may sit idle before the OS sends the first TCP keepalive probe. Only applied where the JDK and the platform expose TCP_KEEPIDLE (Linux and macOS do); elsewhere the system-wide default applies, typically 2 hours. 0 leaves the system default in place. Since v26.9.1 |
Integer |
120 |
|
Seconds between TCP keepalive probes once the first one has gone unanswered. 0 leaves the system default in place. Since v26.9.1 |
Integer |
15 |
|
Number of unanswered TCP keepalive probes after which the connection is declared dead. With the defaults a dead peer is detected about 3 minutes after the connection goes idle. 0 leaves the system default in place. Since v26.9.1 |
Integer |
4 |
|
Path where the SSL certificates are stored |
String |
null |
|
Password to open the SSL key store |
String |
null |
|
Path to the SSL trust store |
String |
null |
|
Password to open the SSL trust store |
String |
null |
|
Use SSL for client connections |
Boolean |
false |
|
Enables the printing of Postgres protocol to the console. Default is false |
Boolean |
false |
|
TCP/IP host name used for incoming connections for Postgres plugin. Default is '0.0.0.0' |
String |
0.0.0.0 |
|
TCP/IP port number used for incoming connections for Postgres plugin. Default is 5432 |
Integer |
5432 |
|
TLS mode for Postgres wire protocol connections, using the shared SSL key/trust store settings ( |
String |
DISABLED |
|
Maximum number of rows the result of one statement may occupy server-side before the first row is sent to a Postgres client, on both the simple-query and the extended-query (Parse/Bind/Describe/Execute) protocol. The server has to see the whole result before it can announce the column set, and the portal fetch size only bounds what each Execute sends, not what the server holds. A statement exceeding the limit is refused with an error; narrow it with a WHERE or LIMIT clause or raise the limit. 0 means unlimited. Since v26.9.1 |
Integer |
1000000 |
|
Default database name for Redis protocol connections. If set, RAM commands (SET, GET, etc.) will use this database’s globalVariables. Empty means no default (requires SELECT command or key prefix) |
String |
|
|
TCP/IP host name used for incoming connections for Redis plugin. Default is '0.0.0.0' |
String |
0.0.0.0 |
|
TCP/IP port number used for incoming connections for Redis plugin. Default is 6379 |
Integer |
6379 |
|
TCP/IP host name used for incoming connections for Mongo plugin. Default is '0.0.0.0' |
String |
0.0.0.0 |
|
TCP/IP port number used for incoming connections for Mongo plugin. Default is 27017 |
Integer |
27017 |
|
Open all the available databases at server startup |
Boolean |
true |
|
Directory containing the database |
String |
${arcadedb.server.rootPath}/databases |
|
Directory containing the backups |
String |
${arcadedb.server.rootPath}/backups |
|
Directory the server reads and writes its configuration files in: |
String |
${arcadedb.server.rootPath}/config |
|
Optional instance id ( |
String |
|
|
Computes the instance id from |
Boolean |
false |
|
Base URL of the ArcadeData customer portal used by the Support tab of Studio and by |
String |
https://portal.arcadedb.com |
|
Client ID (workspace id) of the customer portal. Together with |
String |
|
|
Client key ( |
String |
|
|
Registers the server as an installation of its workspace in the customer portal without anybody opening Studio: once shortly after the start of a server that holds a support key ( |
Boolean |
true |
|
Directory where the server writes its log files. Useful on read-only root filesystems (e.g. Kubernetes |
String |
./log |
|
The default databases created when the server starts. The format is |
String |
|
|
Milliseconds the |
Long |
60000 |
|
The default mode to load pre-existing databases. The value must match a com.arcadedb.engine.PaginatedFile.MODE enum value: {READ_ONLY, READ_WRITE}Databases which are newly created will always be opened READ_WRITE. |
String |
READ_WRITE |
|
TCP/IP host name used for incoming HTTP connections |
String |
0.0.0.0 |
|
TCP/IP port number used for incoming HTTP connections. Specify a single port or a range |
String |
2480-2489 |
|
TCP/IP port number used for incoming HTTPS connections. Specify a single port or a range |
String |
2490-2499 |
|
Number of threads to use in the HTTP server |
Integer |
2 per core |
|
Timeout in seconds for a HTTP session (managing a transaction) to expire |
Long |
5 |
|
Maximum size in bytes for HTTP request body content, measured on the wire. Set to -1 for unlimited size. A request that declares a |
Integer |
100 |
|
Maximum size in bytes an HTTP request body may expand to once its |
Long |
-1 |
|
Budget in ms a single blocking write of a streamed HTTP response ( |
Integer |
60000 |
|
Interval in ms after which a streamed answer ( |
Integer |
5000 |
|
Timeout in seconds for a HTTP authentication session to expire. This timeout is computed from the latest request using the auth token. See Token-Based Authentication. |
Long |
1800 |
|
Maximum number of concurrent HTTP authentication sessions the server keeps in memory. Once reached, a further |
Integer |
10000 |
|
Maximum number of concurrent HTTP authentication sessions a single user may hold. Beyond it, that user’s oldest session is invalidated to make room for the new one, so a login loop recycles only its own sessions and never affects other users. Set to |
Integer |
100 |
|
Server mode between 'development', 'test' and 'production' |
String |
development |
|
Server name |
String |
ArcadeDB_0 |
|
Server plugins to load, see available plugins. Format as comma separated list of: |
String |
|
|
Password for root user to use at first startup of the server. Set this to avoid asking the password to the user |
String |
null |
|
Path to file with password for root user to use at first startup of the server. Set this to avoid asking the password to the user |
String |
null |
|
Root path in the file system where the server is looking for files. By default is the current directory |
String |
null |
|
Default encryption algorithm used for passwords hashing |
String |
PBKDF2WithHmacSHA256 |
|
Time in milliseconds of checking if the server security files have been modified to be reloaded |
Integer |
5000 |
|
Cache size of hashed salt passwords. The cache works as LRU. Use 0 to disable the cache |
Integer |
64 |
|
When true, |
Boolean |
false |
|
Comma-separated literal IP addresses or CIDR ranges (IPv4 and IPv6) of the reverse proxies allowed to vouch, through |
String |
|
|
Number of iterations to generate the salt or user password. Changing this setting does not affect stored passwords |
Integer |
65536 |
|
Size of the queue used as a buffer for unserviced database change events. |
Integer |
1000 |
|
Maximum number of bytes of change-stream frames that may be outstanding towards a single WebSocket subscriber before it is evicted. Frames are sent asynchronously, so a subscriber that never reads accumulates them in the server’s send buffer: the producer-side queue is bounded but a slow consumer is charged to the server’s heap, not to its own. Past this cap the subscription is dropped and the channel closed, which is what the client would experience anyway. 0 disables the cap. Since v26.9.1 |
Long |
16777216 |
|
Maximum number of bytes of WebSocket request-answer frames - a subscription acknowledgement/error, or an insert-session |
Long |
16777216 |
|
Timeout in seconds for a |
Long |
60 |
|
Maximum size in bytes of a single text frame accepted on |
Long |
65536 |
|
Maximum size in bytes of a single text frame accepted on a |
Long |
16777216 |
|
Maximum number of records a single |
Integer |
100000 |
|
Run the server health monitor: one background thread that samples free disk space on the filesystem holding the databases, available heap, and JVM pause times, and writes a WARNING to the server event log when one of them degrades. Each warning is rate limited - 24h for low disk, 30 minutes for heap and JVM pauses - so a server that stays degraded reports it periodically rather than on every 10-second sample. Read at server start. Since v26.10.1 |
Boolean |
true |
|
When true and HA is active, |
Boolean |
false |
|
When |
Long |
100 |
|
Console log format: |
String |
text |
|
In text log mode, append |
Boolean |
false |
|
Hard ceiling on the number of rows the gRPC unary |
Integer |
100000 |
|
Maximum number of rows the gRPC |
Integer |
1000000 |
|
Hard ceiling on the number of rows - or aggregation buckets - one gRPC |
Integer |
1000000 |
|
Maximum time in milliseconds a gRPC |
Long |
60000 |
|
True to enable metrics |
Boolean |
true |
|
True to enable metrics logging |
Boolean |
false |
|
Require authentication on the |
Boolean |
true |
|
Register an OTLP metrics registry alongside the |
Boolean |
false |
|
OTLP metrics export endpoint, used when |
String |
|
|
How often metrics are pushed to |
Long |
60000 |
|
The OpenTelemetry |
String |
arcadedb |
|
Enable OpenTelemetry distributed tracing (requires the optional |
Boolean |
false |
|
OTLP trace export endpoint (gRPC). |
String |
|
|
Parent-based trace sampling ratio in [0.0,1.0]. |
Float |
0.0 |
|
Comma-separated HTTP request paths that never produce a trace span, matched exactly (query string excluded, one trailing slash ignored, no wildcards). The default leaves out the readiness and health probes. The |
String |
/api/v1/ready,/api/v1/health |
|
Force-enable the Studio web tool even when the server runs in |
Boolean |
false |
DATABASE
| Name | Description | Type | Default Value |
|---|---|---|---|
|
Queue implementation to use between 'standard' and 'fast'. 'standard' consumes less CPU than the 'fast' implementation, but it could be slower with high loads |
String |
standard |
|
Size of the total asynchronous operation queues (it is divided by the number of parallel threads in the pool) |
Integer |
1024 |
|
When the asynchronous queue is full at a certain percentage, back pressure is applied |
Integer |
0 |
|
Maximum number of operations to commit in batch by async thread |
Integer |
10240 |
|
Number of asynchronous worker threads. By default it is cores minus 1, but at least 1 |
Integer |
(machine dependent) |
|
Default page size in bytes for new plain LSM-tree indexes (not full-text, geo or vector ones) created without an explicit page size (SQL |
Integer |
262144 |
|
Default page size in bytes for buckets. Default is 65536 |
Integer |
65536 |
|
Mode used to reuse space in pages. Use 'low' to have faster updates consuming more space on disk, |
String |
high |
|
Wipe out record content on delete. If enabled, assures deleted records cannot be analyzed by parsing the raw files and backups will be more compressed, but it also makes deletes a little bit slower |
Boolean |
true |
|
Default timeout for commands (in ms). On a cluster, a write a follower forwards to the leader carries the follower database’s budget, and the leader enforces that budget in place of its own setting. (Since v26.10.1: previously the leader enforced its own value, which could differ from the one the follower waited for.) |
Long |
0 |
|
Reduce warnings in commands to print in console only every X occurrences. Use 0 to disable warnings with commands |
Integer |
100 |
|
Timeout in ms to lock resources during commit. A bulk index build uses |
Long |
5000 |
|
Timeout in ms to acquire the resources of an explicit |
Long |
5000 |
|
Maximum heap, in bytes, that a single |
Long |
64MB (auto-scaled) |
|
Maximum number of OpenCypher execution plans to keep in cache (frequency-based eviction) |
Integer |
300 |
|
Maximum number of parsed OpenCypher statements to keep in cache. A statement must be hit twice to be protected from a burst of one-off query texts (for example queries that embed their values), so prefer parameters and raise this value if you generate many distinct queries. This is the setting that sizes Cypher statement caching; the |
Integer |
300 |
|
Allow LOAD CSV to access local files via |
Boolean |
true |
|
Root directory for LOAD CSV |
String |
(empty) |
|
Default date format using Java SimpleDateFormat syntax. Textual fields (month or day names, e.g. |
String |
yyyy-MM-dd |
|
Default date implementation to use on deserialization. By default java.time.LocalDate is used, but the following are supported: java.util.Calendar, java.util.Date, java.time.LocalDateTime |
Class |
java.time.LocalDate |
|
Default date time format using Java SimpleDateFormat syntax. Textual fields always use the English locale, see |
String |
yyyy-MM-dd HH:mm:ss |
|
Default datetime implementation to use on deserialization. By default java.time.LocalDateTime is used, but the following are supported: java.util.Date, java.util.Calendar, java.time.LocalDateTime, java.time.ZonedDateTime, java.time.Instant. java.util.Date and java.util.Calendar cannot carry sub-millisecond precision, so with them DATETIME_MICROS and DATETIME_NANOS values are returned as java.time.LocalDateTime |
Class |
class java.time.LocalDateTime |
|
When true, a |
Boolean |
false |
|
Percentage (0-100) of memory to free when Page RAM is full |
Integer |
50 |
|
Upper bound on the size of a Customizable Contraction Hierarchy (CCH) attached to a Graph Analytical View, as supergraph arcs (edges plus shortcuts) per edge of the routed graph. Road, logistics and utility networks need a small multiple of their edge count; graphs without small separators (social graphs, graphs with supernodes) need far more, and building them would exhaust the heap. A hierarchy that would exceed the bound is not built: the view reports it as |
Integer |
16 |
|
When true, a Graph Analytical View (GAV/CSR) that is READY (with no pending overlay changes) when the database closes cleanly writes its CSR to disk alongside a freshness certificate (the database’s last committed transaction id at build time). If nothing was committed to the database between that close and the next open, the certificate still matches and the persisted CSR is reused as-is instead of being rebuilt by a full graph scan. Any commit in between invalidates the certificate and falls back to the previous behavior: an async rebuild triggered on open. Set to false to disable persisting the CSR file (e.g. to avoid its disk footprint or the extra write at close). See Graph OLAP Engine. Since v26.9.1 |
Boolean |
true |
|
Milliseconds |
Long |
0 |
|
Milliseconds a query waits, while it is planned or starts, for a Graph Analytical View (GAV/CSR) whose deferred restore from disk is still in flight, so the first count push-down, |
Long |
5000 |
|
Milliseconds a whole-graph algorithm ( |
Long |
60000 |
|
At commit, when the only conflict on an edge-list page is concurrent in-chunk edge appends (which commute), re-apply the appends on top of the newer page version instead of failing the whole transaction with a retryable conflict. Removes the retry storm on super-node (hot vertex) edge insertion. See Super-Nodes. |
Boolean |
true |
|
Size in bytes of the first chunk of a vertex’s edge list. Each further chunk doubles the previous one up to 8192, so the space a vertex allocates is the sum of that series - a smaller first chunk does not necessarily use less space, it just takes more chunks (each with its own header) to reach the same capacity. The best value follows the degree distribution: around 128 suits an average degree near 10, the default suits very sparse graphs, and above degree 100 the setting barely matters. Values below 32 are clamped. See Lightweight Edges. |
Integer |
64 |
|
Approximate number of edges (per vertex, per direction) after which the vertex’s edge list is promoted to the striped super-node layout, spreading further appends over multiple files so concurrent insertions on the same hot vertex do not contend. Forward-incompatible on first use: promotion writes a new record type, so once any vertex promotes the database can no longer be opened by older releases; promotion is one-way. Iteration order on promoted vertices is approximate (newest-generation-first) instead of strict reverse-insertion. 0 disables promotion entirely (databases stay fully readable by older releases). See Super-Nodes. |
Integer |
4096 |
|
Number of stripes (separate edge-list files) a super-node’s edge list is spread over at promotion. The stripes are hosted in a per-type bucket pool of this many files, created once per type at its first promotion (types without super-nodes cost no files). Write parallelism saturates at the number of concurrent writers, so values beyond the CPU cores rarely help. Values below 2 disable promotion entirely. Recorded per vertex at promotion time. See Super-Nodes. |
Integer |
16 |
|
Gremlin engine to use. By default the native |
String |
java |
|
Port of the Gremlin Server the remote |
Integer |
0 |
|
Default timeout for gremlin commands (in ms). Deprecated |
Long |
30000 |
|
Timeout in ms a bulk index build waits for the file locks of one of its commits, replacing |
Long |
60000 |
|
Minimum number of mutable pages for an index to be schedule for automatic compaction. 0 = disabled |
Integer |
10 |
|
Maximum amount of RAM to use for index compaction, in MB |
Long |
300 |
|
Initial number of entries for page cache |
Integer |
65535 |
|
Maximum number of vectors to cache in memory during HNSW graph building. Higher values speed up construction but use more RAM. RAM usage = cacheSize × (dimensions × 4 + 64) bytes. 0 (the default) sizes it automatically: the cache holds the whole corpus when it fits |
Integer |
0 |
|
Maximum share of the JVM heap the auto-sized graph-build cache may use. Only applies when |
Integer |
25 |
|
Maximum number of vectors kept in the per-index search cache. The cache is shared by every query on the index and survives across queries, so a working set that fits stays resident instead of being re-read from the documents (or from the quantized index pages) on every beam-search hop. RAM usage = cacheSize × (dimensions × 4 + 64) bytes. 0 (the default) sizes it automatically from the number of indexed vectors, capped by |
Integer |
0 |
|
Upper bound, as a percentage of the JVM heap currently available rather than of |
Integer |
25 |
|
Maximum number of vectors written since the last graph rebuild that keep a copy in memory. Every write is appended to a delta buffer so the vector is searchable before it reaches the HNSW graph, and only a rebuild drains that buffer - so an ingest that outruns the rebuilds used to grow a second full copy of the corpus in RAM, which is what made a 4.2M x 768-dimension bulk load run out of memory at |
Integer |
0 |
|
Share of the |
Integer |
10 |
|
Maximum number of vector locations to cache in memory per vector index. Set to -1 for unlimited. Each entry uses ~56 bytes. Recommended: 100000 for datasets with 1M+ vectors |
Integer |
-1 |
|
Maximum fraction of an index’s live vectors that a query’s RID allow-list may cover and still resolve the allow-list to its ordinals and score them directly, instead of paying for a |
Float |
0.2 |
|
The |
Float |
0.05 |
|
Number of mutations (inserts/updates/deletes) before rebuilding the HNSW graph index. Higher values reduce rebuild cost but may return slightly stale results. Recommended: 50-200 for read-heavy, 200-500 for write-heavy workloads |
Integer |
100 |
|
Fraction of the current graph size that must accumulate as pending mutations before the HNSW graph is rebuilt, on top of the absolute |
Float |
0.2 |
|
Ceiling on the threshold computed from |
Integer |
50000 |
|
How much work a query may spend scanning vectors written since the last graph rebuild, as a multiple of the work its graph search already does, before a rebuild is triggered to absorb them. Those vectors are answered by a straight scan, so that part of a query grows with how many are waiting while the graph search it supplements grows only with the logarithm of the index size: at the default |
Float |
1.0 |
|
Inactivity timeout in milliseconds before flushing buffered vectors and rebuilding the HNSW graph. When mutations exist but haven’t reached the rebuild threshold, a timer starts after the last mutation. On a graph under 1,000 vectors the rebuild is cheap and fires for any pending mutation count; on a larger graph it only fires once pending mutations reach at least 10% of the effective rebuild threshold, so a single stray insert does not force a full graph rebuild. The size compared against is the number of vectors the index holds, not the part of the graph the session has loaded, so an ingest-then-idle process that never queries is gated the same way. Since v26.10.1 the timer does not fire while a bulk load is open on the database ( |
Integer |
15000 |
|
Share of the currently available heap that an online vector graph rebuild’s estimated peak footprint may occupy before the rebuild is deferred instead of attempted. An online rebuild keeps the old graph resident so searches keep working and pays for a full new build’s working set on top of it; with no gate it simply attempts the rebuild and dies with an OutOfMemoryError when it does not fit. Since v26.10.1 what keeping the old graph resident costs is measured rather than assumed, so a graph served from pages - the shape after a reopen - is not charged as a second copy of itself in memory, and the available heap it is judged against counts the page read cache as reclaimable: a rebuild that fits only by giving some of it up evicts exactly that shortfall first (oldest pages, across every open database, since the cache is shared) and is still deferred if the cache cannot hand those bytes over. A deferred cycle is not lost: pending vectors stay exactly searchable through the in-memory delta buffer, so the cost is a longer delta scan per query rather than wrong or missing results, and the deferral is logged and counted as |
Integer |
90 |
|
Minimum time in milliseconds before another online vector graph rebuild may be attempted after one was deferred for lack of heap (see |
Integer |
30000 |
|
Maximum amount of pages (in MB) to keep in RAM. When unset it is a quarter of the maximum JVM heap (4096 MB under |
Long |
25% of the max heap |
|
Size of the asynchronous page flush queue |
Integer |
512 |
|
When true (the default), a full backup, an HA database verify and an HA snapshot ship read a point-in-time image served from a page-level copy-on-write shadow, so writers keep running at full speed for the duration. When false, or when the shadow exceeds |
Boolean |
true |
|
Memory budget in MB for the copy-on-write shadow of a single point-in-time window. The shadow only holds the pages modified while the window is open, once each, so a short backup on a moderately busy database often never touches the disk at all. Beyond this budget the shadow spills to a scratch file (see |
Long |
64 |
|
Hard limit in MB (memory plus spill file) on a single copy-on-write shadow before the window is abandoned and its consumer falls back to freezing the data files. The default |
Long |
-1 |
|
Directory for the scratch file a copy-on-write shadow spills into once |
String |
|
|
Default timeout for polyglot commands (in ms) |
Long |
10000 |
|
Maximum number of elements (records) allowed in a single query for memory-intensive operations (eg. ORDER BY in heap). If exceeded, the query fails with an OCommandExecutionException. Negative number means no limit. In OpenCypher it also bounds the rows a Cartesian product or a hash join of disconnected patterns buffers, |
Long |
500000 |
|
Milliseconds a parallel scan waits for a result set that is neither read nor closed before giving up: the scan then frees its threads and the next read of that result set fails instead of silently returning fewer rows. A query whose |
Long |
600000 |
|
Share of a type’s records above which an index search gives way to a full scan of the type, when the scan runs on one thread. Before loading any record, the matching index entries are read alone: when more of them match than this share of the records the type holds, the rows come from a scan filtered by the same condition, otherwise the matching records are loaded in physical order rather than in key order. A scan split across W workers of a parallel scan gives way sooner, at this share divided by (1 + W) / 2, because the index entries are read by one thread whatever the parallelism: with the default, 60% of the type for a sequential scan, 24% on 4 workers, 6% on 18. Applies, in SQL and OpenCypher, only where the order the rows arrive in cannot show in the result - the statement aggregates them or sorts them with an |
Float |
0.6 |
|
When true, a full scan of a type is read by several threads, for more throughput on multi-core machines: with or without a |
Boolean |
true |
|
Minimum number of buckets a type needs for its full scans to run in parallel. A type with fewer buckets is scanned sequentially, unless one of its buckets is large enough to be split in page ranges (see |
Integer |
2 |
|
Minimum number of pages of the unit of work a parallel scan cuts a bucket in: a bucket of at least twice as many pages is read by several threads, each on a range of its pages, so a type with a single bucket (the default) is scanned in parallel too. 0 disables the split: each bucket is then read by one thread (since v26.10.1) |
Integer |
32 |
|
Maximum bytes of record content one batch of a parallel scan holds in memory. The parallel scan reads records on its worker threads and hands them over in batches of up to 256 rows; with large records this bound closes a batch earlier. 0 or a negative value removes the bound (row count only) (since v26.10.1) |
Long |
16777216 |
|
Maximum bytes a scan of a bucket reads ahead of the query in one batch. A scan prefetches up to 1,024 records per bucket; with records that span several pages (a vertex with a big nested document) that is a lot of memory no query budget accounts for, and many concurrent queries could exhaust the heap. The batch ends once the bytes it copied out of the pages reach this size, whatever the record count (records that fit their own page are views of the cached page and are not counted). The limit also shrinks as running queries take the heap budget (see |
Long |
1048576 |
|
Maximum memory (in MB) the scans of all the queries running in the JVM may hold read ahead at once, across every bucket of every database. |
Long |
200 |
|
Runs a SQL script of two or more statements that are ALL schema definition DDL ( |
Boolean |
true |
|
Maximum number of distinct outer values whose result a per-record LET subquery ( |
Integer |
128 |
|
Maximum nesting depth of parentheses, brackets, braces (map and JSON literals) and |
Integer |
200 |
|
The same limit for OpenCypher, covering nested parentheses, list and map literals, function arguments, pattern parentheses, |
Integer |
200 |
|
Maximum number of clauses ( |
Integer |
500 |
|
Maximum number of parsed statements to keep in cache. A statement must be hit twice to be protected from a burst of one-off query texts (for example queries that embed their values), so prefer parameters and raise this value if you generate many distinct queries |
Integer |
300 |
|
Memory budget, in MB and per shard, for keeping decoded TimeSeries data in memory so that reading the same compacted block twice decodes it once. This is what makes a repeated query - a dashboard polling the latest point of a host, for example - answer without re-reading and re-decoding the block it already read. Since the budget is per shard, the worst case for one type is this value times its |
Long |
(auto) |
|
Number of retries in case of MVCC exception |
Integer |
3 |
|
Cap, in milliseconds, on the random wait before the next transaction retry: an exponential backoff with full jitter, drawn from |
Integer |
100 |
|
Starting size, in milliseconds, of the transaction retry backoff window, doubled on each further attempt up to |
Integer |
2 |
|
Refuses, with a retryable |
Boolean |
true |
|
Uses the WAL |
Boolean |
true |
|
Number of concurrent files to use for tx log. 0 or a negative value = available cores, which is also the default |
Integer |
(machine dependent) |
|
Flushes the WAL on disk at commit time. It can be 0 = no flush, 1 = flush without metadata and 2 = full flush (fsync). In |
Integer |
0 |
|
Default number of buckets to create per type |
Integer |
1 |
Available Plugins
| Name | server.plugins-String |
|---|---|
Gremlin |
|
gRPC |
|
MongoDB |
|
Postgres |
|
Prometheus |
|
Redis |
|
gRPC
The gRPC server is implemented by the GrpcServerPlugin, which is bundled in the full distribution but not started by default. To enable it, register the plugin in server.plugins (see available plugins):
-Darcadedb.server.plugins=gRPC:com.arcadedb.server.grpc.GrpcServerPlugin
Once enabled, the server listens on port 50051 by default. Since v26.11.1 every grpc. setting below is a registered server setting, so it can be supplied in the server configuration file, as an environment variable or as a JVM system property (-Darcadedb.grpc.). Before that, only grpc.port was, and the others worked as system properties only: a grpc.tls.enabled written in the configuration file was ignored and the endpoint stayed in cleartext. An invalid grpc.mode now makes the server refuse to start instead of starting no listener. The server.plugins setting itself is a standard server setting and can be supplied the same ways.
| Name | Description | Type | Default Value |
|---|---|---|---|
|
Start the gRPC server when the plugin is registered. Set to |
Boolean |
true |
|
Port for the standard gRPC server. A registered server setting since v26.9.1 (so it is also resolved from environment variables and listed in the settings API), because HA reads it to advertise a peer’s gRPC endpoint - see the |
Integer |
50051 |
|
Host/interface to bind to: every local address the name resolves to. Applies to the standard server only; the xDS server (mode |
String |
0.0.0.0 |
|
Server mode: |
String |
standard |
|
Port for the xDS server (used when |
Integer |
50052 |
|
Enable TLS for the gRPC server. Only |
Boolean |
false |
|
Path to the TLS certificate chain file (required when |
String |
(none) |
|
Path to the TLS private key file (required when |
String |
(none) |
|
Maximum inbound message size, in MB |
Integer |
100 |
|
Enable the gRPC server reflection service (used by tools such as |
Boolean |
true |
|
Enable the standard gRPC health-checking service |
Boolean |
true |
|
Advertise support for message compression |
Boolean |
true |
|
Force compression on all outbound messages |
Boolean |
false |
|
Compression algorithm used when |
String |
gzip |
In addition to the plugin-level keys above, the gRPC service honors four registered SERVER settings that bound result materialization and protect against limitless or slow clients pinning worker threads and exhausting heap: server.grpcQueryMaxResultRows, server.grpcTimeSeriesMaxResultRows, server.grpcStreamMaxMaterializedRows, and server.grpcStreamWriteTimeoutMs (see the SERVER settings table). Unlike the grpc.* keys, these are standard server settings and can be supplied as JVM system properties or environment variables.